5
2
Microsoft Security Advisory 2963983
Vulnerability in Internet Explorer Could Allow Remote Code Execution Published: April 26, 2014
General Information
Executive Summary
Microsoft is aware of limited, targeted attacks that attempt to exploit a vulnerability in Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11. The vulnerability is a remote code execution vulnerability. The vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. An attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website.
My understanding is that you are suppose to use Internet Explorer: Enhanced Security Configuration and or disable ActiveX/Adobe Flash and use Trusted Sites to be able to use IE securely.
My problem is that I have to use IE because of a certain web application that uses activex.
My question, if I use another browser that uses the same Rendering Engine as IE will I still be safe? Avant Browser uses the same engine that displays the web pages and does work fine for my web application. But will it be Safe from that Security Bug?
There are even plugins and extensions for Chrome/Firefox that will open a web page using IE Web Browser Control within Chrome/Firefox. These browsers use builtin ActiveX, but Chrome & Firefox are not effected by this securiy issue. Will it be safe though?
This question has been edited to genericise it and make it apply to future scenarios, now that the update is out – kinokijuf – 2014-05-03T21:28:30.653
sorry I rolled the question back because the bounty was for a specific question relating to an issue I have to resolve. – Logman – 2014-05-03T22:02:39.453
please don’t edit it back, the question in its current state is outdated now that KB2964358 is out. Answer to your current question is: update your system. Answer to the generic question was given by @harrymc.
– kinokijuf – 2014-05-03T22:04:52.913